PT-2026-4471 · Miniserve · Miniserve

Published

2026-01-23

·

Updated

2026-01-25

·

CVE-2025-67124

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions miniserve version 0.32.0
Description A time-of-check to time-of-use (TOCTOU) and symlink race condition exists in miniserve when uploads are enabled. This can allow an attacker to overwrite arbitrary files outside the intended upload directory in deployments where the attacker can create or replace filesystem entries in the upload destination directory. The issue occurs during upload finalization.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling uploads until a patch is available.

Exploit

Fix

Time Of Check To Time Of Use

Link Following

Weakness Enumeration

Related Identifiers

CVE-2025-67124
GHSA-MXC8-4JQF-368Q

Affected Products

Miniserve